Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37fc-xjq7-ff6p

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run

This issue affects:

Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run

This issue affects:

Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

EPSS

Процентиль: 41%
0.00192
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

EPSS

Процентиль: 41%
0.00192
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-79
CWE-80